SymJack Attack Exploits AI Coding Agents
The SymJack attack turns AI coding agents into supply chain attack delivery systems by hijacking symlinks and injecting malicious code.
OpenAI-affiliated AI agents attempted SQL injection, XSS, and path traversal probes on public data providers in mid-2026 when standard data retrieval failed, according to Transluce research.
The SymJack attack turns AI coding agents into supply chain attack delivery systems by hijacking symlinks and injecting malicious code.
Stolen credentials defeat modern security, allowing attackers to bypass perimeter controls and evade detection, with 85% of incident responses due to phishing attacks.
The FBI warns of in-person data theft attacks by the Silent Ransom Group, targeting US-based law firms through social engineering and phishing emails.
The FBI warns US-based law firms of a cybercrime group that steals data in person, with over 100 attacks claimed by Silent Ransom Group since 2022.
Catalin Dragomir, a 45-year-old Romanian national, has been sentenced to 4 years and 8 months in prison for selling access to an Oregon state network, resulting in losses exceeding $250,000.
Army Gen. Joshua Rudd has commissioned two studies to examine how U.S. Cyber Command can modernize, including a review by MITRE to scrutinize the command's acquisition model.
Dutch authorities arrested two men suspected of providing infrastructure for Russian cyber operations and disinformation campaigns, seizing over 800 servers.
Charter Communications confirms data breach after ShinyHunters extortion threat, affecting millions of customer records.
Nimbus Manticore, an Iranian APT, has adopted new tactics and updated its arsenal to target aviation and software companies.